Daniel Gardham

dblp:222/6614 · DBLP profile ↗
← Back
12ranked-venue papers
3as first author
8since 2021 · last 2026
0000-0002-8856-1093ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 12 · 3 first-author · 8 since 2021
YearPublicationVenuePosition
2026 Policy-Based Access Tokens: Privacy-Preserving Verification for Digital Identity
Kiran Pun, Daniel Gardham, Nick Frymann
ACNS (2)2
2026 Ringslip: Ring Signatures from the Lattice Isomorphism Problem
Callum London, Daniel Gardham, Constantin Catalin Dragan
SECRYPT (1)2
2025 Dynamic Group Signatures with Verifier-Local Revocation
abstract
Group Signatures are fundamental cryptographic primitives that allow users to sign a message on behalf of a predefined set of users, curated by the group manager. The security properties ensure that members of the group can sign anonymously and without fear of being framed. In dynamic group signatures, the group manager has finer-grained control over group updates while ensuring membership privacy (i.e., hiding when users join and leave). The only known scheme that achieves standard security properties and membership privacy has been proposed by Backes et al. CCS 2019. However, they rely on an inefficient revocation mechanism that re-issues credentials to all active members during every group update, and users have to rely on a secure and private channel to join the group. In this paper, we introduce a dynamic group signature that supports verifier local revocation, while achieving strong security properties, including membership privacy for users joining over a public channel. Moreover, when our scheme is paired with structure-preserving signatures over equivalence class it enjoys a smaller signature size compared to Backes et al. Finally, as a stand-alone contribution we extend the primitive Asynchronous Remote Key Generation (Frymann et al. CCS 2020) with trapdoors and introduce new security properties to capture this new functionality, which is fundamental to the design of our revocation mechanism.
Callum London, Daniel Gardham, Constantin Catalin Dragan
CSF2
2024 Crypto Dark Matter on the Torus - Oblivious PRFs from Shallow PRFs and TFHE
Martin R. Albrecht, Alex Davidson, Amit Deo, Daniel Gardham
EUROCRYPT (6)4
2023 Generalised Asynchronous Remote Key Generation for Pairing-Based Cryptosystems
Nick Frymann, Daniel Gardham, Mark Manulis, Hugo Nartz
ACNS (1)2
2023 Asynchronous Remote Key Generation for Post-Quantum Cryptosystems from Lattices
abstract
Asynchronous Remote Key Generation (ARKG), introduced by Frymann et al. at CCS 2020, allows for the generation of unlinkable public keys by third parties, for which corresponding private keys may be later learned only by the key pair’s legitimate owner. These key pairs can then be used in common public-key cryptosystems, including signatures, PKE, KEMs, and schemes supporting delegation, such as proxy signatures. The only known instance of ARKG generates discrete-log-based keys.In this paper, we introduce new ARKG constructions for lattice-based cryptosystems. The key pairs generated using our ARKG scheme can be applied to lattice-based signatures and KEMs, which have recently been selected for standardisation in the NIST PQ process, or as alternative candidates.In particular, we address challenges associated with the noisiness of lattice hardness assumptions, which requires a new generalised definition of ARKG correctness, whilst preserving the security and privacy properties of the former instantiation. Our ARKG construction uses key encapsulation techniques by Brendel et al. (SAC 2020) coined Split KEMs. As an additional contribution, we also show that Kyber (Bos et al., EuroS&P 2018) can be used to construct a Split KEM. The security of our protocol is based on standard LWE assumptions. We also discuss its use with selected candidates from the NIST process and provide an implementation and benchmarks.
Nick Frymann, Daniel Gardham, Mark Manulis
EuroS&P2
2022 Revocable Hierarchical Attribute-Based Signatures from Lattices
Daniel Gardham, Mark Manulis
ACNS1
2022 Unlinkable Delegation of WebAuthn Credentials
Nick Frymann, Daniel Gardham, Mark Manulis
ESORICS (3)2
2020 Biometric-Authenticated Searchable Encryption
Daniel Gardham, Mark Manulis, Constantin Catalin Dragan
ACNS (2)1
2020 Asynchronous Remote Key Generation: An Analysis of Yubico's Proposal for W3C WebAuthn
abstract
WebAuthn, forming part of FIDO2, is a W3C standard for strong authentication, which employs digital signatures to authenticate web users whilst preserving their privacy. Owned by users, WebAuthn authenticators generate attested and unlinkable public-key credentials for each web service to authenticate users. Since the loss of authenticators prevents users from accessing web services, usable recovery solutions preserving the original WebAuthn design choices and security objectives are urgently needed. We examine Yubico's recent proposal for recovering from the loss of a WebAuthn authenticator by using a secondary backup authenticator. We analyse the cryptographic core of their proposal by modelling a new primitive, called Asynchronous Remote Key Generation (ARKG), which allows some primary authenticator to generate unlinkable public keys for which the backup authenticator may later recover corresponding private keys. Both processes occur asynchronously without the need for authenticators to export or share secrets, adhering to WebAuthn's attestation requirements. We prove that Yubico's proposal achieves our ARKG security properties under the discrete logarithm and PRF-ODH assumptions in the random oracle model. To prove that recovered private keys can be used securely by other cryptographic schemes, such as digital signatures or encryption schemes, we model compositional security of ARKG using composable games by Brzuska et al. (ACM CCS 2011), extended to the case of arbitrary public-key protocols. As well as being more general, our results show that private keys generated by ARKG may be used securely to produce unforgeable signatures for challenge-response protocols, as used in WebAuthn. We conclude our analysis by discussing concrete instantiations behind Yubico's ARKG protocol, its integration with the WebAuthn standard, performance, and usability aspects.
Nick Frymann, Daniel Gardham, Franziskus Kiefer, Emil Lundberg, Mark Manulis, Dain Nilsson
CCS2
2019 Hierarchical Attribute-Based Signatures: Short Keys and Optimal Signature Length
Daniel Gardham, Mark Manulis
ACNS1
2018 Hierarchical Attribute-Based Signatures
Constantin Catalin Dragan, Daniel Gardham, Mark Manulis
CANS2